Insights on the Scams Prevention Framework for Australian Banks
Translating SPF Obligations Into Practical Compliance Actions for Australian Banks
-
September 11, 2026
-
The draft rules and sector codes for Australia’s Scams Prevention Framework (‘SPF’) place direct accountability on banks to protect consumers from scams. With regulators explicitly prioritising scam prevention, banks must demonstrate compliance and show how reasonable steps are operationalised in their organisation. Here we share our insights into how banks can translate reasonable steps into practical implementation, applying our experience as the expert in a recent Australian Securities Investment Commission (‘ASIC’) enforcement action.
What Is the SPF and Who Is Impacted?
Introduced by the Federal Government in February 2025, the SPF Act established the overarching framework and principles for scam prevention, detection, disruption and response.1 On 28 May 2026, Treasury introduced the SPF exposure draft for consultation, which outlines the practical mandatory obligations or “codes” for banking, telecommunications and digital platforms to combat scams at every stage – from governance, prevention, detection, disruption to response.2 Non-compliance carries penalties of up to $50 million, with SPF Rules in force from 1 September 2026, while broader sector code obligations, statements of compliance, record-keeping mandates, and Australian Financial Complaints Authority (‘AFCA’) dispute pathways take full effect on 31 March 2027.3 Regulated sectors are expected to increase to include superannuation funds and cryptocurrency wallets.4
What Does “Reasonable Steps” Mean in Practice?
In our experience as an expert in a recent ASIC enforcement, “reasonable steps” must be demonstrated through a fraud and scam risk framework and tailored controls to prevent, detect, disrupt, and respond to evolving scam typologies. Banks should ensure that they:
- Keep abreast of current and evolving scam typologies. There is an expectation that for well-known scam typologies, the bank would have had sufficient time to build its control defences to protect customers from harm before a scam incident occurs.
- Build a governance framework to monitor and manage the risk of scams. This should articulate the quantified risk appetite to fraud and scam losses in terms of both the bank and customer losses. Management reporting should track losses against risk appetite, with action/investment to enhance controls when losses exceed risk appetite. The assessment of risk appetite should have reference to the size, complexity, and business mix of the bank, aligned with CPS 220 and CPS 230, which require banks to have proportionate controls.
- Conduct a comprehensive Scam Risk Assessment. This considers the risks and bank controls by scam typology. The Scam Risk Assessment should be detailed, by channel and payment rail. Consideration of controls should also be sufficiently detailed, for example at a transaction monitoring test level. Where there are control gaps and design weaknesses, and where key controls are not operating effectively, the bank should have a plan or program to uplift controls.
- Be conscious of the ease and cost to implement additional controls. If there are controls widely used in the market that are easy to implement and not cost prohibitive, and the bank has not adopted these controls, this will likely not be seen favourably by the regulator. That is, if the additional controls are considered easy to implement, there may be an expectation that the bank should have had these controls in place. If the decision has been made not to invest in a control, the bank should document the reasons why, with other compensating controls that sufficiently mitigate the risk without the need for further investment, if this is the case.
Note this process is not ‘set and forget’. As scam typologies evolve, it is important to regularly report and assess how the bank is protecting customers from harm.
Applying Reasonable Steps Across the Five Principles
| SPF Draft Obligations | Recommended Reasonable Steps for SPF Compliance |
|---|---|
|
Governance
— Maintain a Scam Governance Framework. |
— SPF obligations should be incorporated into the bank’s Enterprise Risk Register, with a compliance gap analysis. |
|
Prevent
— Have reasonable processes and resources to manage scam risk.
— Confirm payee details before transfers proceed and warn customers of account name mismatches and that there may be a scam, with the option not to proceed. |
— “Reasonable” considers proportionality of controls given scam risks and losses faced by the bank’s customers, types of customer or vulnerability, channels and staying aligned or ahead of industry practice. |
|
Detect
— Act on received scam intelligence within 28 days.
— Monitor transaction and account activity to identify actionable scam intelligence, including transaction activity inconsistent with those previously made and changes to customer contact details or authorisation settings. |
ASIC has expectations that banks will deploy the following detection controls across channels:
— Behavioural biometrics as part of reasonable systems. |
|
Disrupt
— Take proportionate, risk-based action to disrupt scams.
— As soon as practicable, reverse the scam transaction or take reasonable steps to assist the sending bank to reverse the transaction. |
— Conduct a network analysis to identify parties to the scam and to ensure completeness of coverage of scam-relevant parties. |
|
Respond
— Automatically reimburse scam victims for verified scam losses below $3,000. |
— Entities should conduct a gap analysis of existing scam response playbooks, recognising that what is considered ‘reasonable’ will likely be assessed relative to the bank’s size or scale, business mix (product and customer) and complexity. |
The table below maps SPF draft obligations and additional Banking Code requirements against recommended reasonable steps for each of the five principles, drawing on our experience working with regulated entities on SPF readiness.
Conclusion: Act Now To Get Reasonable Steps Right
The SPF imposes binding obligations on banks to demonstrate proactive, documented, and proportionate scam controls. Independent assurance can help banks identify gaps, strengthen control frameworks, and build resilience against evolving scam typologies, while protecting both consumers and the organisation. With the implementation deadline approaching and regulatory scrutiny already apparent, banks should act now to assess and strengthen their scam prevention frameworks and be ready to evidence reasonable steps.
Implementing a scam risk management framework will take time, so banks need to be planning and operationalising compliance now.
Footnotes:
1: Natalie Faulkner, “Australia’s Scams Prevention Framework: New Protections & Penalties,” FTI Consulting (12 March 2025).
2: “Competition and Consumer (Scams Prevention Framework—SPF Codes) Instrument 2026,” The Treasury - Australian Government (28 May 2026), Page 1.
3: Ibid
4: “Scams Prevention Framework – Protecting Australians from scams,” Australian Government, The Treasury (3 February 2025), Page 2.
Published
September 11, 2026
Key Contacts
Senior Managing Director, Leader of Australia Risk & Investigations
Senior Director